June 7, 2012

Google Play, which is the Android application marketplace for a large number of smart phones, has several holes in the system that allows malicious applications to be downloaded by unsuspecting users. Google has a security system referred to as Bouncer, which is supposed to keep this malicious software out. Two well-known smart phone researchers said they’ve found at least 20 techniques to bypass the security software. The weakness with the Bouncer software is due to the complexity of the software and that it is based on a popular emulator that has had its share of vulnerabilities in the past.

The biggest downfall of the Bouncer security is that malicious software can bypass the security by disguising malicious behavior until after the application has cleared the malicious-intent review. By making malicious applications look normal, the apps will pass the malicious intent review and be distributed to the users. This weakness is not something that is simple to patch, therefore it may be a while before security around Google Play and Bouncer is increased.

30/40